Okta: Phishers Bypass MFA by Pushing Weaker Options

Cybersecurity Dive · Medium sophistication
Last updated October 8, 2026

Okta analyzed thousands of real social-engineering incidents and found most account takeovers still rely on stealing passwords and then bypassing MFA through push prompts or one-time codes. Okta described multiple campaigns where attackers phished credentials and then talked victims into using weaker login methods, including a ruse claiming a hardware security key “is not working.”

How the attack worked

Okta analyzed roughly 6,000 real social-engineering events and found a consistent pattern behind most account takeovers. Attackers first steal a password through phishing, then work to defeat whatever MFA protection is in place. In one campaign starting in August 2026, a phishing kit stole both passwords and one-time login codes. The kit presented a fake login window with an invented excuse, telling victims their hardware security key was not working and urging them to use a one-time passcode instead. Once attackers gained access, they changed the victim's MFA enrollment to point at attacker-controlled infrastructure, letting them retain control of the account even if the original credentials were later reset.

Okta also described two other campaigns that used different entry points. One in mid-2025 used Slack direct messages to direct victims to phishing sites, and another in 2023 began with text messages. Both ultimately funneled victims toward a fake login page designed to harvest credentials and authentication codes.

Why it succeeded

The data shows MFA alone is not a guaranteed defense. Okta found that 58% of account takeovers involved compromised push notifications, 36% involved theft of app-based codes, and 22% involved theft of SMS-based codes. A password theft combined with push-notification subversion appeared in 47% of takeovers. These weaker authentication methods are phishable: a convincing pretext and a realistic fake login page are often enough to get a victim to hand over a code or approve a push, especially when the attacker frames it as the only option because a stronger method

Key findings

  • Okta analyzed roughly 6,000 social-engineering events and found 87% of account takeovers involved compromised passwords.
  • Many takeovers also involved MFA bypass/abuse: 58% involved compromised push notifications, 36% involved theft of app-based codes, and 22% involved theft of SMS-based codes.
  • A common pattern was password theft plus push-notification subversion (47% of account takeovers).
  • Okta described a campaign (starting Aug. 2026) where a phishing kit stole both passwords and one-time login codes and used a ruse to push victims away from phishing-resistant authentication.
  • After gaining access, attackers changed victims’ MFA enrollments to attacker-controlled infrastructure.
  • Okta also described campaigns using Slack direct messages (mid-2025) and text messages (2023) to send victims to phishing sites.

Who’s being targeted

  • Commonly targeted roles: All employees, IT/Identity administrators, Security operations, Slack users, Finance and other high-risk business users.
  • Affected industries: Multiple industries (enterprise users of MFA/SSO).
  • Attack channels: website, slack, smishing.
  • Impersonated: Organization login/SSO page (fake lookalike), Someone contacting the user via Slack DM (not specified in article), Sender via SMS/text message (not specified in article).

Red flags to watch for

  • Login page discourages using a security key and pushes a weaker method “instead”
  • Unexpected request to re-authenticate and provide a one-time code
  • URL/domain mismatch or unusual sign-in flow compared to the normal SSO experience
  • Unsolicited Slack DM with a login link
  • Pressure to click immediately instead of using a known bookmark/app
  • Link goes to an unfamiliar domain or prompts unexpected MFA steps
  • Unexpected security/verification text with a link
  • Sense of urgency to act immediately
  • Link does not match official corporate domains
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How do phishers get victims to bypass MFA?

Okta found attackers phish passwords and then use pretexts, such as claiming a hardware security key is not working, to convince victims to use a weaker method like a one-time passcode instead.

What percentage of account takeovers involved compromised passwords?

Okta analyzed roughly 6,000 social-engineering events and found that 87% of account takeovers involved compromised passwords.

Does phishing-resistant authentication actually help?

Yes. Okta found that requiring phishing-resistant authentication would have stopped 88% of the account takeover attempts in its dataset.

What happens after attackers gain account access?

Okta described attackers changing victims' MFA enrollments to their own infrastructure after gaining access, allowing them to maintain control of the account.

Read the video transcript

You log in with your hardware security key… and the screen says, “Your hardware key is not working. Use a one-time passcode instead.” Okta saw this for real: a phishing kit that steals your password and your one-time code, then locks you out by changing your MFA. The whole trick is pushing you off your security key onto weaker MFA. Sometimes it starts with a Slack DM: “Hey, can you sign in here to review this?” You click, see a familiar-looking login, and it suddenly insists on a one-time code instead of your usual key or normal SSO flow. If any login page or message tells you your hardware key “is not working” and pushes you to a one-time code, stop. Don’t switch methods, open your normal SSO bookmark or app and sign in from there instead.

Similar attacks

Passkey Helpdesk Scam Hijacks Microsoft Accounts

Passkey Helpdesk Scam Hijacks Microsoft Accounts

Microsoft described two real-world campaigns: an invoice fraud blast impersonating executives to trick finance teams into ACH payments, and a passkey-themed helpdesk scam that steals or bypasses authentication to take over Microsoft cloud accounts. In the second campaign, victims are called or…

September 13, 2026
Passkey Helpdesk Scam Hijacks Microsoft 365

Passkey Helpdesk Scam Hijacks Microsoft 365

Microsoft reports active intrusions where attackers trick employees with “passkey/SSO update” helpdesk pretexts delivered by phone, SMS, or even Microsoft Teams. Victims are sent to lookalike Microsoft sign-in pages or guided through device-code sign-in, letting attackers capture session access and…

September 9, 2026
Attackers Phish via Teams & Slack, Not Email

Attackers Phish via Teams & Slack, Not Email

Research and incident examples show attackers increasingly using trusted collaboration tools (like Microsoft Teams and Slack) to impersonate IT/support or known community members, then push victims to phishing sites, approve MFA prompts, or run malicious files. Because messages come through…

August 20, 2026
Fraudulent Gov Email and Passkey Lures Hit Orgs

Fraudulent Gov Email and Passkey Lures Hit Orgs

The bulletin describes real-world social engineering where staff were tricked into disclosing sensitive data or access. In one case, Revolut employees responded to fraudulent information requests sent from a real government-domain email account, exposing extensive customer records. Separately,…

September 14, 2026
AI Voice “Apple Support” Phishing + Fake IT Helpdesk

AI Voice “Apple Support” Phishing + Fake IT Helpdesk

This news roundup describes real social-engineering operations where attackers impersonate trusted support teams to trick people into giving up secrets. One campaign uses email/SMS/WhatsApp plus AI voice calls pretending to be Apple Support to steal iPhone passcodes, while another uses phishing…

August 27, 2026
AI “Apple Support” Calls Steal iPhone Passcodes

AI “Apple Support” Calls Steal iPhone Passcodes

Researchers say a phishing-as-a-service platform called AnonyMousKIT targets people who recently lost or had an iPhone stolen by pretending to be “Apple Support.” The operation uses email/SMS/WhatsApp and AI-assisted voice calls to convince victims to share their iPhone passcode and follow a…

August 26, 2026